Leadership: Protect Quality, Independence and Trust
A Big Four firm does not compete only through its technical expertise, global network, technology platforms or client relationships. Its most valuable asset is trust.
Clients trust the firm with commercially sensitive information, strategic decisions, financial records, personal data and complex regulatory matters. Regulators trust the firm to exercise professional judgement and uphold required standards. Investors, employees, governments and the wider public expect the firm to behave responsibly, independently and ethically.
This trust can take decades to build and can be weakened by a single serious failure.
Protecting quality, independence and trust is therefore not merely the responsibility of audit, legal, compliance, risk or cybersecurity teams. It is a core leadership responsibility and an essential part of business strategy.
An exceptional Managing Director ensures that commercial pressure never weakens professional judgement. They create an environment in which quality is rewarded, concerns can be raised safely, risk functions have genuine authority and leaders are held accountable for both financial results and professional standards.
The central leadership principle is simple:
The firm should never pursue revenue, growth, speed or client satisfaction at the expense of professional quality, independence, legality, confidentiality or public trust.
1. Why quality and trust are strategic assets
In professional services, reputation directly affects commercial performance.
A trusted firm is more likely to:
- Win major and sensitive engagements.
- Retain strategically important clients.
- Attract talented employees and senior leaders.
- Maintain constructive relationships with regulators.
- Form partnerships with governments and technology providers.
- Enter regulated and high-risk markets.
- Receive access to confidential information.
- Recover more effectively when problems occur.
- Command premium pricing for specialist expertise.
- Influence public and industry discussions.
A firm that loses trust may experience:
- Regulatory investigations.
- Financial penalties.
- Litigation and legal exposure.
- Loss of audit or advisory clients.
- Restrictions on business activities.
- Increased professional indemnity costs.
- Damage to employee morale.
- Difficulty recruiting senior talent.
- Higher client scrutiny.
- Reduced access to strategic opportunities.
- Long-term damage to the firm’s brand.
Trust should therefore be treated as a form of organisational capital.
Like financial capital, it must be accumulated, protected and carefully allocated. Every engagement, client acceptance decision, public statement, technology deployment and leadership appointment either strengthens or weakens that capital.
2. Quality must be defined broadly
Quality should not be understood only as technical accuracy or compliance with a checklist.
In a Big Four firm, quality includes:
- Correct application of professional standards.
- Reliable and evidence-based judgement.
- Clear documentation.
- Appropriate review and challenge.
- Independence from improper influence.
- Accurate communication with clients and stakeholders.
- Protection of confidential information.
- Ethical use of data and technology.
- Competent staffing.
- Effective supervision.
- Timely escalation of concerns.
- Transparency about limitations and uncertainty.
- Delivery of work that is appropriate for its intended purpose.
A technically correct report can still represent poor-quality work when:
- Important risks were not communicated.
- Evidence was incomplete.
- Independence was compromised.
- The team lacked relevant expertise.
- Senior reviewers did not provide meaningful challenge.
- The client misunderstood the limitations of the work.
- Confidential data was handled improperly.
- Artificial intelligence was used without adequate validation.
- Commercial pressure influenced the conclusion.
The Managing Director must therefore establish a broad and practical definition of quality that applies across audit, tax, deals, consulting, legal, technology and managed services.
3. Set the tone from the top
Employees judge leadership priorities by observing decisions, not by reading value statements.
A firm may publicly claim that quality comes first, but employees will form a different conclusion when they see:
- High-revenue leaders protected despite repeated control failures.
- Quality concerns ignored to meet deadlines.
- Risk teams excluded from commercial decisions.
- People promoted mainly because of sales performance.
- Employees criticised for slowing down a client engagement.
- Serious incidents described as isolated administrative mistakes.
- Weak consequences for leaders who compromise standards.
The Managing Director must communicate through visible action that quality, independence and ethical conduct are non-negotiable.
This includes:
- Supporting teams that refuse inappropriate client requests.
- Pausing engagements when evidence or controls are inadequate.
- Rewarding leaders who escalate risks early.
- Holding senior people accountable for repeated quality failures.
- Giving risk and quality leaders access to executive decision-making.
- Discussing quality performance alongside financial performance.
- Being transparent about major failures and corrective actions.
- Refusing work that creates unacceptable risk.
The most powerful leadership signal occurs when a commercial opportunity conflicts with professional standards.
When leaders consistently choose quality over short-term revenue, employees learn that the firm’s values are real.
4. Protect professional judgement from commercial pressure
Commercial discipline is necessary. A professional-services firm must generate revenue, manage margins, satisfy clients and compete effectively.
However, commercial objectives must never determine professional conclusions.
Pressure can arise in many forms:
- A client threatens to move work to a competitor.
- An engagement is significantly over budget.
- A deadline is approaching.
- A senior partner has made a commitment to the client.
- A major proposal depends on maintaining a relationship.
- A client disputes an uncomfortable finding.
- A team is encouraged to reduce testing or review.
- A project is expected to proceed despite unresolved risks.
- A technology solution is promoted before validation is complete.
The Managing Director must create safeguards that allow professionals to exercise independent judgement.
These safeguards may include:
- Clear escalation routes outside the engagement hierarchy.
- Independent technical consultations.
- Protected access to ethics, legal and risk teams.
- Mandatory review for high-risk judgements.
- Policies preventing financial consequences from influencing professional conclusions.
- Monitoring of excessive workload and deadline pressure.
- Confidential channels for employees to report concerns.
- Executive review of engagements where commercial and quality interests conflict.
- Protection from retaliation for those who raise legitimate concerns.
Leaders should regularly ask:
- Are teams being given enough time to perform quality work?
- Are engagement economics creating pressure to reduce necessary procedures?
- Are junior employees comfortable challenging senior decisions?
- Are client expectations influencing professional conclusions?
- Are leaders rewarded for raising difficult issues?
- Are quality concerns being reclassified as delivery problems?
- Are teams afraid that escalation will damage their careers?
Professional judgement becomes vulnerable when people believe that commercial success matters more than doing the right thing.
5. Strengthen audit and professional quality
Audit and professional quality require continuous leadership attention because failures can create significant public, regulatory and financial consequences.
The Managing Director should ensure that quality-management systems are not limited to annual inspections or policy documents.
A strong quality system should include:
- Clear quality objectives.
- Defined accountability at engagement, service-line and regional levels.
- Competency requirements for important roles.
- Risk-based engagement reviews.
- Independent quality inspections.
- Technical consultation mechanisms.
- Effective supervision and review.
- Root-cause analysis.
- Remediation tracking.
- Quality indicators.
- Escalation procedures.
- Continuous learning from incidents and near misses.
Leadership should review both outcome and behavioural indicators.
Outcome indicators may include:
- Inspection results.
- Restatements or corrected reports.
- Regulatory findings.
- Complaints.
- Litigation.
- Missed control requirements.
- Data or security incidents.
- Engagement withdrawals.
- Rework levels.
Behavioural indicators may include:
- Late consultation with specialists.
- Excessive working hours.
- High staff turnover.
- Repeated deadline extensions.
- Low challenge in review notes.
- Unresolved differences of opinion.
- Weak documentation.
- Over-reliance on a small number of senior people.
- Low usage of escalation channels.
- Recurring issues within particular teams.
A low number of reported concerns does not necessarily indicate a healthy culture. It may indicate that employees do not feel safe speaking up.
6. Preserve independence
Independence is central to the credibility of professional services, particularly audit and assurance.
Independence must exist both in fact and in appearance.
A firm may believe that its judgement was not influenced, but public trust can still be damaged when relationships, financial interests or services create the appearance of compromised objectivity.
Independence risks may arise from:
- Providing prohibited services to audit clients.
- Financial interests in clients.
- Close personal or family relationships.
- Employment relationships.
- Excessive dependence on fees from one client.
- Long association with senior client management.
- Contingent-fee arrangements.
- Commercial partnerships.
- Joint ventures.
- Technology alliances.
- Gifts, hospitality or incentives.
- Shared data or systems.
- Pressure from influential clients.
The Managing Director should ensure that independence controls are practical, current and understood across the organisation.
Leadership activities may include:
- Reviewing significant independence breaches.
- Monitoring high-risk client relationships.
- Assessing whether new services create independence concerns.
- Ensuring global and regional systems are aligned.
- Reviewing the impact of acquisitions and alliances.
- Strengthening pre-approval processes.
- Improving financial-interest monitoring.
- Ensuring employees receive role-specific training.
- Applying consequences consistently.
- Evaluating both actual and perceived independence risks.
The leadership test is not only whether an activity is technically permitted.
Leaders should also ask:
- Could this relationship reasonably weaken public confidence?
- Would we be comfortable explaining this decision to a regulator?
- Could an informed external observer question our objectivity?
- Are we interpreting the rules too narrowly?
- Is the commercial benefit influencing our assessment?
7. Manage conflicts of interest
A global professional-services firm may serve clients that compete with one another, participate in the same transaction, operate across connected industries or have conflicting legal and commercial interests.
Conflicts can be:
- Actual.
- Potential.
- Perceived.
- Emerging.
- Confidentiality-related.
- Commercial.
- Personal.
- Organisational.
- Regulatory.
Examples include:
- Advising both parties to a transaction.
- Supporting competitors on similar strategies.
- Using information from one client to benefit another.
- Serving a client while holding a financial interest in an opposing organisation.
- Moving employees between sensitive engagements.
- Supporting a government body and a regulated organisation on related matters.
- Providing assurance over systems the firm helped design.
- Participating in alliances that affect professional objectivity.
Effective conflict management requires more than database checks.
The Managing Director should ensure that the organisation has:
- Clear client and engagement acceptance procedures.
- Reliable conflict-checking systems.
- Defined information barriers.
- Independent review of complex conflicts.
- Legal and ethical consultation.
- Rules for staff movement between engagements.
- Procedures for disclosure and consent where appropriate.
- Ongoing monitoring when circumstances change.
- Escalation for cross-border or cross-service-line conflicts.
Leaders must recognise that a conflict can emerge after an engagement begins. Client ownership, transaction structures, alliances and competitive relationships may change.
Conflict assessment should therefore be continuous rather than limited to initial acceptance.
8. Protect client confidentiality
Clients provide professional-services firms with highly sensitive information, including:
- Financial records.
- Commercial strategies.
- Personal data.
- Legal advice.
- Merger and acquisition plans.
- Pricing information.
- Intellectual property.
- Security information.
- Employee records.
- Government data.
- Product roadmaps.
- AI models and datasets.
A confidentiality breach can damage the client, the firm and public trust.
The Managing Director should ensure confidentiality is protected through a combination of policy, technology, culture and accountability.
Key controls may include:
- Data classification.
- Role-based access.
- Strong authentication.
- Encryption.
- Secure collaboration tools.
- Device management.
- Information barriers.
- Data-loss prevention.
- Monitoring of privileged access.
- Secure retention and disposal.
- Restrictions on removable media.
- Controls for external sharing.
- Secure development practices.
- Third-party security assessments.
- Incident-detection and response capabilities.
Leadership should also address common behavioural risks, such as:
- Discussing client matters in public places.
- Sharing documents through personal accounts.
- Using unapproved AI tools.
- Sending information to the wrong recipient.
- Retaining client files longer than necessary.
- Downloading sensitive data to local devices.
- Using production data for testing.
- Providing excessive system access.
- Reusing client material without permission.
Confidentiality must be part of everyday professional behaviour, not only an annual training requirement.
9. Maintain constructive regulatory relationships
Regulators play an essential role in protecting markets, investors, clients and the public.
The Managing Director should treat regulatory relationships as long-term relationships based on credibility, transparency and professional respect.
A defensive or purely legalistic approach can weaken trust.
Strong regulatory engagement includes:
- Timely and accurate communication.
- Transparent reporting of material issues.
- Evidence-based responses.
- Honest acknowledgement of weaknesses.
- Clear remediation plans.
- Consistent messages across leadership.
- Respectful challenge where interpretations differ.
- Early communication when significant risks emerge.
- Demonstration of learning and improvement.
Leaders should avoid:
- Minimising serious findings.
- Providing incomplete information.
- Treating regulatory engagement as a public-relations exercise.
- Delaying disclosure while seeking a more favourable narrative.
- Blaming individual employees without examining systemic causes.
- Making remediation commitments that the firm cannot deliver.
- Presenting temporary fixes as long-term solutions.
A strong relationship does not mean the regulator will agree with the firm. It means the regulator believes the firm is honest, competent, responsive and committed to improvement.
10. Control legal exposure
Legal risk can arise from many areas, including:
- Professional negligence.
- Contractual disputes.
- Misrepresentation.
- Confidentiality breaches.
- Employment issues.
- Intellectual-property disputes.
- Data-protection violations.
- Competition law.
- Regulatory non-compliance.
- Cybersecurity incidents.
- Third-party failures.
- AI-generated errors.
- Cross-border restrictions.
- Inadequate documentation.
The Managing Director should ensure that legal teams are involved early in important decisions rather than only after a problem occurs.
Legal-risk management should include:
- Clear engagement contracts.
- Defined scope and responsibilities.
- Appropriate liability provisions.
- Accurate documentation of decisions.
- Review of high-risk deliverables.
- Legal assessment of new services.
- Intellectual-property controls.
- Data-processing agreements.
- Third-party contract review.
- Dispute-escalation procedures.
- Litigation-readiness planning.
- Document-retention requirements.
Leaders should understand that poor documentation can turn a manageable issue into a major legal problem.
Important decisions should clearly record:
- What was known.
- What was uncertain.
- Which risks were identified.
- Who made the decision.
- Which alternatives were considered.
- What evidence supported the conclusion.
- Which controls were required.
- When the decision would be reviewed.
11. Strengthen cybersecurity
A Big Four firm is an attractive target because it holds valuable information from many major organisations.
Cybersecurity must therefore be treated as an enterprise risk and business responsibility, not only an IT function.
The Managing Director should ensure that cybersecurity covers:
- Identity and access management.
- Endpoint protection.
- Cloud security.
- Network security.
- Application security.
- Software supply-chain risk.
- Third-party risk.
- Data security.
- Vulnerability management.
- Threat intelligence.
- Security monitoring.
- Incident response.
- Business continuity.
- Disaster recovery.
- Employee awareness.
- Privileged-access management.
- Secure software development.
Executive oversight should focus on questions such as:
- Which systems and data are most critical?
- Who has access to sensitive client information?
- Are privileged accounts adequately controlled?
- How quickly can the firm detect an intrusion?
- Are critical vulnerabilities being remediated?
- Are third parties meeting required standards?
- Can the firm continue operating during a major cyberattack?
- Are backups protected and regularly tested?
- Are acquisition targets assessed for cyber risk?
- Are cloud environments configured consistently?
- Are employees reporting suspicious activity?
Cybersecurity performance should be discussed in business terms, including:
- Potential client impact.
- Operational disruption.
- Regulatory exposure.
- Financial consequences.
- Reputation damage.
- Recovery capability.
12. Protect personal data
Professional-services firms process significant amounts of personal data relating to employees, clients, customers, suppliers and members of the public.
Data protection requires more than obtaining consent or publishing a privacy notice.
Strong data-governance practices include:
- Lawful and transparent processing.
- Purpose limitation.
- Data minimisation.
- Accuracy.
- Retention control.
- Security.
- Accountability.
- Data-subject rights.
- Cross-border transfer controls.
- Privacy impact assessments.
- Processor oversight.
- Breach notification.
- Privacy by design.
The Managing Director should challenge teams that collect or retain data without a clear need.
Leaders should ask:
- Why do we need this data?
- Are we using it for the purpose for which it was collected?
- Could the objective be achieved with less data?
- How long should the data be retained?
- Who can access it?
- Is personal data being transferred internationally?
- Are automated decisions affecting individuals?
- Can we respond to access or deletion requests?
- Are vendors processing data appropriately?
- What would happen if the data were exposed?
Good data protection reduces both risk and operational complexity.
13. Govern artificial intelligence responsibly
Artificial intelligence creates significant opportunities, but it also introduces new risks.
These risks may include:
- Inaccurate outputs.
- Hallucinations.
- Bias and discrimination.
- Confidentiality breaches.
- Intellectual-property infringement.
- Lack of explainability.
- Insecure model integration.
- Prompt injection.
- Data leakage.
- Over-reliance on automated decisions.
- Inappropriate use of personal data.
- Weak human oversight.
- Model drift.
- Third-party dependency.
- Regulatory non-compliance.
- Unclear accountability.
The Managing Director should ensure that AI governance covers the full lifecycle:
- Use-case identification.
- Risk classification.
- Data assessment.
- Model and vendor selection.
- Design.
- Development.
- Testing.
- Approval.
- Deployment.
- Monitoring.
- Incident management.
- Retirement.
High-risk AI systems should require stronger controls, such as:
- Independent validation.
- Human approval.
- Bias testing.
- Security testing.
- Privacy assessment.
- Explainability requirements.
- Model documentation.
- Logging and traceability.
- Usage restrictions.
- Ongoing performance monitoring.
- Clear user disclosures.
- Defined appeal or correction processes.
Leaders should resist pressure to deploy AI merely because competitors are doing so.
The correct question is not:
Can we use AI?
It is:
Should we use AI for this purpose, and can we do so safely, lawfully, ethically and effectively?
14. Promote ethical conduct
Rules cannot anticipate every situation.
Employees need ethical judgement to make decisions when policies are incomplete, competing interests exist or the correct action is commercially inconvenient.
Ethical leadership requires:
- Clear behavioural expectations.
- Accessible ethics advice.
- Confidential reporting channels.
- Protection against retaliation.
- Consistent investigation.
- Fair disciplinary processes.
- Visible consequences for misconduct.
- Leadership transparency.
- Regular discussion of ethical dilemmas.
The Managing Director should create an environment in which people can ask:
- Is this legal?
- Is this permitted by policy?
- Is this professionally responsible?
- Is this fair?
- Could this harm a client or the public?
- Would we be comfortable if this decision became public?
- Are we taking advantage of information or influence?
- Are we treating all stakeholders honestly?
- Does this decision reflect the values we claim to hold?
Ethics becomes meaningful when it guides decisions that are difficult, expensive or unpopular.
15. Review material quality issues
The Managing Director should receive regular reporting on significant quality, risk and trust issues.
A material issue may involve:
- Serious regulatory findings.
- Significant client complaints.
- Independence violations.
- Confidentiality breaches.
- Cyber incidents.
- AI failures.
- Legal claims.
- Professional misconduct.
- Repeated inspection failures.
- Major control deficiencies.
- Public controversy.
- Significant third-party failures.
Executive review should establish:
- What happened?
- Who was affected?
- What immediate action was taken?
- Is the issue contained?
- Is regulatory notification required?
- What is the potential client impact?
- What is the legal and financial exposure?
- What caused the issue?
- Could the same issue exist elsewhere?
- Which leader owns remediation?
- How will progress be independently verified?
- What will be communicated internally and externally?
The objective is not to become involved in every operational detail. It is to ensure accountability, adequate resources, cross-firm learning and appropriate escalation.
16. Challenge recurring control weaknesses
Repeated control failures are a leadership warning.
When the same issue appears across multiple engagements, teams or years, the organisation may have a systemic problem.
Recurring weaknesses may indicate:
- Unclear accountability.
- Poorly designed processes.
- Insufficient training.
- Weak technology.
- Excessive workload.
- Inadequate supervision.
- Misaligned incentives.
- Cultural resistance.
- Lack of consequences.
- Ineffective remediation.
- Fragmented ownership.
The Managing Director should challenge explanations such as:
- “It was human error.”
- “It was an isolated incident.”
- “The employee has now left.”
- “We have reminded the team.”
- “Additional training will be provided.”
These responses may be appropriate components of remediation, but they do not explain why the organisation allowed the failure to occur.
Leaders should ask:
- Why was the error possible?
- Why was it not detected earlier?
- Why did existing controls fail?
- Has this happened elsewhere?
- Are incentives contributing to the problem?
- Is the process too complex?
- Are teams adequately resourced?
- Does management information reveal the issue?
- Who is accountable for preventing recurrence?
17. Review high-risk clients and engagements
Not every client or engagement presents the same level of risk.
Higher-risk circumstances may include:
- Financial distress.
- Complex ownership.
- Politically exposed persons.
- Sanctions exposure.
- Weak governance.
- Aggressive accounting or tax positions.
- Repeated disputes with advisers.
- Unusual payment arrangements.
- High corruption risk.
- Regulatory investigation.
- Significant public controversy.
- Weak internal controls.
- Pressure on professional judgement.
- Insufficient access to information.
- High reliance on emerging technology.
- Material use of AI.
The Managing Director should ensure that high-risk engagements receive:
- Enhanced client acceptance.
- Senior leadership oversight.
- Specialist involvement.
- Independent review.
- Clear contractual protections.
- Stronger documentation.
- More frequent risk monitoring.
- Defined escalation triggers.
- Exit criteria.
Leadership must also be willing to decline or terminate relationships.
Revenue already earned or future commercial potential should not prevent the firm from leaving a relationship that creates unacceptable legal, ethical, professional or reputational risk.
18. Monitor pressure on employees
Employees are often the first to recognise when standards are being compromised.
However, they may remain silent when they fear:
- Damage to their career.
- Negative performance reviews.
- Removal from important work.
- Conflict with powerful leaders.
- Being described as difficult.
- Loss of promotion opportunities.
- Social exclusion.
- Retaliation from the client.
- Being blamed for delays.
The Managing Director should actively assess whether employees feel pressured to compromise standards.
Useful methods include:
- Confidential culture surveys.
- Independent listening sessions.
- Exit interviews.
- Ethics-line analysis.
- Focus groups.
- Workload monitoring.
- Review of overtime patterns.
- Analysis of project overruns.
- Direct engagement with junior employees.
- Monitoring repeated deadline pressure.
- Reviewing employee-relations cases.
Leaders should not rely exclusively on reports from senior management. Information should be gathered from different levels of the organisation.
A psychologically safe organisation does not remove accountability. It creates an environment in which people can raise concerns, admit uncertainty and challenge decisions without fear of unfair consequences.
19. Give risk functions sufficient authority
Risk, quality, independence, legal, privacy and cybersecurity functions must have genuine authority.
Their role is not simply to advise commercial leaders and then accept whatever decision is made.
Depending on the issue, they should be able to:
- Require additional controls.
- Escalate decisions.
- Delay approval.
- Stop deployment.
- Reject an engagement.
- Require independent review.
- Mandate remediation.
- Report directly to executive leadership.
- Access necessary information.
- Challenge senior commercial leaders.
The Managing Director should examine whether risk leaders have:
- Appropriate seniority.
- Direct access to governance bodies.
- Adequate funding.
- Sufficient specialist capability.
- Independence from revenue targets.
- Protection when challenging powerful stakeholders.
- Clear decision rights.
- Transparent escalation routes.
A risk function that can be ignored is not an effective control function.
20. Perform root-cause analysis
Root-cause analysis should look beyond the immediate mistake.
A quality failure may initially appear to have been caused by one employee. Deeper analysis may identify:
- Inadequate training.
- Unreasonable deadlines.
- Poor system design.
- Weak supervision.
- Ambiguous policies.
- Lack of specialist support.
- Conflicting incentives.
- Excessive workload.
- Incomplete data.
- Ineffective communication.
- Normalisation of shortcuts.
- Weak accountability.
A useful root-cause process should examine:
Individual factors
- Did the individual have the required competence?
- Was judgement reasonable based on available information?
- Were expectations clear?
- Was misconduct involved?
Team factors
- Was the team appropriately staffed?
- Did supervisors provide effective review?
- Were concerns discussed openly?
- Did the team have access to specialists?
Process factors
- Was the process clear and practical?
- Were controls well designed?
- Did systems support compliance?
- Were responsibilities defined?
Leadership factors
- Were deadlines unrealistic?
- Did leaders create commercial pressure?
- Were previous warning signs ignored?
- Were quality and risk priorities clear?
Cultural factors
- Were people comfortable escalating concerns?
- Were shortcuts accepted?
- Were high performers treated differently?
- Did employees believe that quality mattered?
The purpose of root-cause analysis is not to remove individual accountability. It is to prevent the organisation from treating systemic problems as isolated personal failures.
21. Detect emerging risks
Exceptional leaders do not focus only on known risks. They improve the firm’s ability to identify risks that are developing.
Emerging risks may arise from:
- New regulations.
- AI and automation.
- Geopolitical instability.
- New cyber threats.
- Changing public expectations.
- Technology concentration.
- Cloud-provider dependency.
- Supply-chain disruption.
- Climate-related events.
- New business models.
- Acquisitions.
- Managed services.
- Cross-border data use.
- Platform-based delivery.
- Changing workforce models.
Detection mechanisms may include:
- Horizon scanning.
- Regulatory monitoring.
- Threat intelligence.
- External advisory panels.
- University partnerships.
- Scenario planning.
- Client feedback.
- Analysis of near misses.
- Industry incident reviews.
- Technology risk assessments.
- Employee reporting.
- Data-driven risk indicators.
The Managing Director should regularly ask:
- Which risks are growing faster than our controls?
- Where are we relying on assumptions that may no longer be valid?
- Which new services fall outside traditional governance models?
- Which third parties have become critical dependencies?
- What risks are employees discussing informally but not escalating?
- Which external events could rapidly damage trust?
22. Rehearse crisis-response scenarios
A crisis is not the time to design the organisation’s response.
The firm should rehearse realistic scenarios, such as:
- A major cyberattack.
- Loss of confidential client data.
- A serious audit failure.
- A significant AI-related incident.
- Regulatory intervention.
- Public allegations of misconduct.
- A conflict-of-interest exposure.
- A major technology outage.
- A third-party breach.
- A senior leader misconduct case.
- A whistleblower allegation.
- A legal injunction.
- A major media investigation.
Crisis exercises should test:
- Decision-making authority.
- Escalation speed.
- Internal communication.
- Client communication.
- Regulatory notification.
- Legal response.
- Media handling.
- Technical containment.
- Business continuity.
- Evidence preservation.
- Employee support.
- Board oversight.
- Recovery planning.
Exercises should expose weaknesses, not confirm that existing plans are adequate.
Leaders should examine:
- Did the right people receive information quickly?
- Was ownership clear?
- Were decisions documented?
- Did legal, risk, communications and technology teams coordinate?
- Could the firm continue critical operations?
- Were messages accurate and consistent?
- Did teams understand notification obligations?
- Were senior leaders willing to acknowledge uncertainty?
- How quickly could the firm identify affected clients?
23. Integrate quality into performance management
Quality and trust will not become strategic priorities when leaders are evaluated mainly on revenue, sales and margin.
Performance assessment should include:
- Quality outcomes.
- Inspection results.
- Ethical leadership.
- Risk management.
- People development.
- Collaboration.
- Timely escalation.
- Client outcomes.
- Compliance with independence requirements.
- Remediation delivery.
- Contribution to organisational learning.
Promotion decisions should consider how results were achieved.
A leader who generates significant revenue while creating recurring quality failures should not be treated as a top performer.
The Managing Director should ensure that:
- Quality failures affect performance outcomes.
- Strong risk leadership is recognised.
- People who raise concerns are protected.
- Repeat misconduct has clear consequences.
- Reward systems do not encourage excessive risk-taking.
- Client satisfaction is not measured without considering professional integrity.
24. Make quality part of client strategy
Quality should be positioned as a source of client value.
Clients benefit when the firm helps them:
- Identify risk early.
- Improve governance.
- Strengthen controls.
- Make better-informed decisions.
- Protect sensitive information.
- Meet regulatory expectations.
- Use technology responsibly.
- Increase organisational resilience.
- Build public confidence.
The firm should not present quality as an administrative burden.
For example, strong AI governance can help a client scale artificial intelligence more confidently. Strong data protection can improve customer trust. Effective cybersecurity can protect business continuity. High-quality assurance can improve investor confidence.
The Managing Director should encourage teams to explain how quality, trust and risk management contribute to commercial and strategic outcomes.
25. Measure trust and quality
Financial performance is relatively easy to measure. Trust and quality require a broader set of indicators.
A quality and trust dashboard may include:
Professional quality
- Inspection outcomes.
- Rework.
- Technical consultation rates.
- Review completion.
- Documentation quality.
- Engagement withdrawals.
- Client complaints.
Independence and conflicts
- Confirmed breaches.
- Late declarations.
- Conflict escalations.
- Repeat issues.
- Resolution time.
Confidentiality and data protection
- Data incidents.
- Misdirected communications.
- Access-control violations.
- Data-subject request performance.
- Retention-policy compliance.
- Third-party findings.
Cybersecurity
- Critical vulnerabilities.
- Detection and response times.
- Phishing-reporting rates.
- Privileged-access reviews.
- Recovery-test performance.
- Third-party risk status.
AI risk
- High-risk AI use cases.
- Model-validation status.
- AI incidents.
- Human-oversight exceptions.
- Unapproved tool usage.
- Model-performance degradation.
Culture
- Employee confidence in speaking up.
- Perceived pressure to compromise.
- Retaliation concerns.
- Leadership credibility.
- Workload sustainability.
- Ethics-line trends.
Metrics should support judgement rather than replace it.
A dashboard showing low incident numbers may create false confidence when employees are reluctant to report concerns.
26. Establish effective governance
Quality and trust require clear governance.
A strong structure may include:
- Board or executive oversight.
- A regional quality and risk committee.
- Service-line quality leaders.
- Independent risk, legal and compliance functions.
- Technology and cybersecurity governance.
- Data and AI governance boards.
- Engagement-level quality owners.
- Defined escalation pathways.
- Regular reporting.
- Independent assurance.
Decision rights should be explicit.
For material issues, the organisation should know:
- Who can approve?
- Who can challenge?
- Who can stop the activity?
- Who must be consulted?
- Who owns remediation?
- Who reports to regulators?
- Who communicates with clients?
- Who verifies closure?
Ambiguous accountability creates delay, duplication and unmanaged risk.
27. A practical leadership operating model
The Managing Director can embed quality and trust through a structured operating rhythm.
Weekly activities
- Review major incidents and emerging concerns.
- Examine high-risk client or engagement decisions.
- Resolve escalated independence or conflict issues.
- Review critical cyber and data risks.
- Challenge delays in remediation.
- Speak directly with quality and risk leaders.
Monthly activities
- Review the quality and trust dashboard.
- Analyse recurring control weaknesses.
- Examine culture and workload indicators.
- Review high-risk AI deployments.
- Evaluate regulatory commitments.
- Review third-party risks.
- Assess whether risk functions have sufficient capacity.
Quarterly activities
- Conduct deep dives into selected risk themes.
- Review root-cause analysis.
- Examine performance and promotion consequences.
- Review high-risk client portfolios.
- Test crisis readiness.
- Assess emerging risks.
- Meet regulators or external stakeholders where appropriate.
Annual activities
- Review the firm’s quality and risk strategy.
- Assess the effectiveness of governance.
- Refresh risk appetite.
- Evaluate crisis-response capability.
- Review major technology and data dependencies.
- Test succession for critical quality and risk roles.
- Confirm that incentives support professional standards.
28. Questions an exceptional leader should ask
A Managing Director protecting quality, independence and trust should regularly ask:
About quality
- Where are our most significant quality risks?
- Which problems are recurring?
- Are teams receiving enough time and expertise?
- Where are reviews becoming procedural rather than substantive?
About independence
- Are we complying with both the spirit and the letter of the rules?
- Could an informed observer question our objectivity?
- Are commercial relationships creating hidden pressure?
About culture
- Do employees feel safe raising concerns?
- What happens to people who challenge senior leaders?
- Are high-revenue individuals held to the same standards?
About risk functions
- Can risk leaders stop activity when necessary?
- Do they have sufficient authority and resources?
- Are they involved early enough?
About clients
- Which relationships create disproportionate risk?
- Are there clients we should not continue serving?
- Are teams being pressured by client expectations?
About technology
- Which systems create concentrated operational risk?
- Are AI systems adequately governed?
- Can we detect misuse or failure quickly?
About trust
- Which decisions could be difficult to explain publicly?
- Where could a technically compliant decision still damage confidence?
- What are we doing today that future stakeholders may judge differently?
29. Common leadership failures
Several leadership behaviours weaken quality and trust.
Treating quality as the responsibility of specialists
Quality becomes marginalised when business leaders assume that risk and compliance teams own it.
Focusing only on reported incidents
Reported incidents represent only known problems. Leaders must also examine weak signals, near misses and employee concerns.
Protecting senior commercial performers
Different standards for powerful individuals undermine the entire control environment.
Accepting superficial remediation
Training and policy reminders are insufficient when incentives, processes or leadership behaviours caused the issue.
Prioritising speed over control
Urgency should not become a justification for bypassing professional standards.
Managing reputation instead of managing the problem
Public relations cannot substitute for containment, accountability and remediation.
Using legal compliance as the maximum standard
An action may be legally permitted but still professionally inappropriate, ethically questionable or harmful to public trust.
Treating trust as intangible
Trust can and should be considered in investment, governance, performance and strategic decisions.
30. What exceptional leadership looks like
An exceptional Managing Director:
- Makes quality a visible strategic priority.
- Protects professional judgement.
- Gives risk functions genuine authority.
- Holds senior leaders accountable.
- Encourages employees to speak up.
- Reviews systemic causes.
- Acts before risks become crises.
- Invests in cybersecurity and data protection.
- Governs AI responsibly.
- Maintains constructive regulatory relationships.
- Declines unacceptable work.
- Responds transparently when failures occur.
- Connects quality with client and business value.
- Protects the long-term reputation of the firm.
The leader understands that trust is not maintained through statements alone.
It is maintained through thousands of daily decisions:
- Which clients the firm accepts.
- Which services it provides.
- How employees are rewarded.
- How concerns are handled.
- How technology is governed.
- How incidents are investigated.
- How leaders behave under pressure.
- Whether the firm chooses long-term credibility over short-term gain.
Conclusion
Protecting quality, independence and trust is one of the most important responsibilities of a Big Four Managing Director.
It requires more than compliance oversight. It requires strategic leadership, cultural consistency, strong governance, investment in capability, transparent accountability and the courage to make commercially difficult decisions.
The clearest test of leadership is not what happens when quality and commercial interests are aligned. It is what happens when they conflict.
Exceptional leaders make it clear that:
- Professional judgement cannot be purchased.
- Independence cannot be negotiated.
- Confidentiality cannot be treated casually.
- Risk cannot be ignored for convenience.
- Ethical conduct applies to every person, regardless of seniority.
- Public trust is more valuable than any individual engagement.
Quality and trust should not sit beside the business strategy as separate compliance topics.
They should shape the clients the firm serves, the services it develops, the technologies it deploys, the people it promotes and the decisions its leaders make.
A firm that protects trust can continue to grow, innovate and influence markets.
A firm that sacrifices trust for short-term commercial success eventually places the entire organisation at risk.
Discussion
Comments
Share feedback or questions about this page. No account required.
Loading comments…